CVE-2017-7540

rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.
References
Link Resource
https://github.com/svenfuchs/safemode/pull/23 Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:safemode_project:safemode:*:*:*:*:*:ruby:*:*

History

No history.

Information

Published : 2017-07-21 22:29

Updated : 2024-02-04 19:29


NVD link : CVE-2017-7540

Mitre link : CVE-2017-7540

CVE.ORG link : CVE-2017-7540


JSON object : View

Products Affected

safemode_project

  • safemode
CWE
NVD-CWE-noinfo CWE-184

Incomplete List of Disallowed Inputs